It was discovered that Libtasn1 incorrectly handled certain ASN.1 data structures. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service. (CVE-2014-3467)
It was discovered that Libtasn1 incorrectly handled negative bit lengths. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-3468)
It was discovered that Libtasn1 incorrectly handled certain ASN.1 data. An attacker could exploit this with specially crafted ASN.1 data and cause applications using Libtasn1 to crash, resulting in a denial of service. (CVE-2014-3469)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtasn1-3-bin",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-3-dev",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-6",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-6-dev",
"binary_version": "3.4-3ubuntu0.1"
},
{
"binary_name": "libtasn1-bin",
"binary_version": "3.4-3ubuntu0.1"
}
]
}
{
"ecosystem": "Ubuntu:14.04:LTS",
"cves": [
{
"id": "CVE-2014-3467",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2014-3468",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2014-3469",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}